Quick Start
Configure a security scanner in yourbunfig.toml: [install.security] scanner = "@acme/bun-security-scanner"When configured, Bun will:
- Scan all packages before installation
- Display security warnings and advisories
- Cancel installation if critical vulnerabilities are found
- Automatically disable auto-install for security
How It Works
Security scanners analyze packages duringbun install, bun add, and other package operations. They can detect: - Known security vulnerabilities (CVEs)
- Malicious packages
- License compliance issues
- …and more!
Security Levels
Scanners report issues at two severity levels:-
fatal- Installation stops immediately, exits with non-zero code -
warn- In interactive terminals, prompts to continue; in CI, exits immediately
Using Pre-built Scanners
Many security companies publish Bun security scanners as npm packages that you can install and use immediately.Installing a Scanner
Install a security scanner from npm:bun add -d @acme/bun-security-scanner
Consult your security scanner’s documentation for their specific package name and installation instructions. Most scanners will be installed with
bun add.Configuring the Scanner
After installation, configure it in yourbunfig.toml: [install.security] scanner = "@acme/bun-security-scanner"
Enterprise Configuration
Some enterprise scanners might support authentication and/or configuration through environment variables:# This might go in ~/.bashrc, for example export SECURITY_API_KEY="your-api-key" # The scanner will now use these credentials automatically bun installConsult your security scanner’s documentation to learn which environment variables to set and if any additional configuration is required.